目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-54322— Daytona 授权问题漏洞

CVSS 7.7 · High EPSS 0.19% · P8

Possible ATT&CK Techniques 1AI

T1078.004 · Cloud Accounts

Affected Version Matrix 1

ベンダープロダクトVersion Rangeステータス
daytonaiodaytona< 0.185.0affected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-54322の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Daytona: Cross-org IDOR in organization role update/delete — any org owner can rewrite or destroy another org's roles
ソース: CVE Program / CVE List V5
脆弱性説明
Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0, Daytona's organization role update and delete endpoints authorized the caller as an owner of the organization named in the request path, but resolved and mutated the target role by its identifier alone, without verifying the role belonged to that organization. An authenticated user who owns any organization (organizations are self-service) could therefore modify the permissions of, or delete, a role belonging to a different organization, given that role's identifier. This vulnerability is fixed in 0.185.0.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L
ソース: CVE Program / CVE List V5
脆弱性タイプ
通过用户控制密钥绕过授权机制
ソース: CVE Program / CVE List V5
脆弱性タイトル
Daytona 授权问题漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Daytona Daytona是美国Daytona团队的一个安全且弹性的基础架构运行时环境,专为 AI 生成的代码执行和代理工作流而设计。 Daytona 0.185.0之前版本存在授权问题漏洞,该漏洞源于组织角色更新和删除端点未验证角色是否属于请求路径中的组织,可能导致已验证用户修改或删除其他组织的角色权限。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
daytonaiodaytona < 0.185.0 -

II. CVE-2026-54322の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム
Qwen3.6-35B-A3B · 4934 文字数
Pro+限定の内容:
脆弱性再現の録画(実際のサンドボックス構築 + トリガー、限定)
脆弱性の原理を深く分析
トリガー条件と影響範囲
完全な実行可能POCコード
攻撃チェーンと緩和策の提案
POCパッケージのダウンロード
月間100件以上のAI生成枠

III. CVE-2026-54322のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-54322 厂商安全公告 (1)

Same Patch Batch · daytonaio · 2026-06-23 · 6 CVEs total

CVE-2026-543208.4 HIGHDaytona: Cross-tenant organization takeover via invitation acceptance with an unverified e
CVE-2026-543217.0 HIGHDaytona: Public sandbox previews remain accessible for up to one hour after being made pri
CVE-2026-543246.5 MEDIUMDaytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizat
CVE-2026-543235.9 MEDIUMDaytona: Git credential leak via git clone with TLS verification disabled
CVE-2026-543194.2 MEDIUMDaytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox

IV. 関連脆弱性

V. CVE-2026-54322へのコメント

まだコメントはありません


コメントを残す